Which Group Manages GPOs in Microsoft Entra Domain Services?

You have a Microsoft Entra Domain Services domain named contoso.com. You need to provide an administrator with the ability to manage Group Policy Objects (GPOs). The solution must use the principle of least privilege. To which group should you add the administrator?

  1. AAD DC Administrators Source Reference Answer
  2. Domain Admins
  3. Schema Admins
  4. Enterprise Admins
  5. Group Policy Creator Owners

Community Votes

A
71%
E
29%

71% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your understanding of Entra ID Managed AD-specific permission models versus traditional on-premises Active Directory groups, with the common trap being the selection of familiar legacy roles.

Managing Group Policy Objects in Microsoft Entra Domain Services requires assigning permissions to the AAD DC Administrators group to ensure compliance with the principle of least privilege. Community consensus confirms this cloud-native administrative group replaces legacy on-premises roles for GPO management.

Option E (Group Policy Creator Owners) is the most frequent incorrect choice because it traditionally provides least-privilege GPO creation in on-premises environments, but it is not applicable or supported within the Entra ID Managed AD architecture.

Community Discussion (4 comments)

SunRise 👍 2 Selected: A
Please do your research by if my analysis is right: The question is talking about Entra DS, not on-prim, so if I am not mistake there no group as GP Creator Owner there, the the Answer should be A
Krayzr 👍 3 Selected: A
AAD AD Admins
VirtuaTech 👍 2 Selected: E
Group Policy Creator Owners = Just the right access to just manage GPOs
Ksk08 👍 2
Answer is E

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The AAD DC Administrators group is the designated built-in security group for performing administrative tasks on domain controllers in Microsoft Entra Domain Services. Adding the administrator to this group grants the precise permissions needed to create, edit, and link Group Policy Objects without granting excessive domain-wide control. Microsoft explicitly recommends this group for least-privilege GPO management in the managed service environment.

Why the Other Options Are Wrong

Options B, C, and D represent legacy on-premises enterprise groups that grant unrestricted domain or forest-level access, directly violating the principle of least privilege. While Option E correctly limits GPO creation in traditional Active Directory, it does not exist or function as intended within Entra ID Managed AD. Relying on these traditional groups ignores the architectural differences and security boundaries enforced by the cloud-managed directory service.

Community Comment Notes

Candidates frequently debated between options A and E, reflecting a common knowledge gap regarding cloud versus on-premises AD. Comment [1] accurately highlights that Entra DS operates differently and lacks the traditional Group Policy Creator Owners role, steering the correct choice toward A. Comment [3] reinforces the AAD DC Administrators designation, aligning with official Microsoft training materials. The vote distribution demonstrates that practical experience with Entra ID Managed AD significantly improves accuracy over theoretical on-premises assumptions.

Official Reference

Exam Strategy

Always map administrative requirements to the specific platform's built-in role-based access control model rather than defaulting to legacy on-premises group names. Review Microsoft's official Entra ID Managed AD documentation to understand how cloud directory services abstract traditional Active Directory permission structures.

Related Analysis

← Back to AZ-800 Study Guide